Cookie policy

CARDO sets two cookies. Both are strictly necessary, and there is no third-party tracking.

Effective TODO_EFFECTIVE_DATE

Draft, not for publication. The legal entity, registered address, contact addresses and effective date are still placeholders in content/site.ts. This document also needs review by a solicitor before it goes live.

Cookies we use

NamePurposeLifetimeType
cardo_sessionKeeps you signed in. HttpOnly, so it cannot be read by JavaScript. Secure and SameSite in production.14 daysStrictly necessary
cardo_csrfProtects against cross-site request forgery by pairing a cookie value with a request header.SessionStrictly necessary

What we do not use

No analytics cookies, no advertising or retargeting pixels, no social media cookies, no session recording, and no third-party tracking of any kind. The marketing pages you are reading now set no cookies at all.

Under the Privacy and Electronic Communications Regulations, consent is required for cookies that are not strictly necessary for a service the user has asked for. Both of ours are strictly necessary: without them you cannot stay signed in, and requests cannot be protected against forgery. Since there is nothing optional to consent to, asking would be theatre.

Controlling cookies

You can block or delete cookies in your browser settings. Blocking these two will prevent you from signing in, because there is no other way for the service to recognise your session.

For everything else we do with personal data, see the privacy policy.